Skip to content

Learn

Learning Hub

Short, structured explanations of the ideas every tool assumes, plus practice environments and reference material — clearly separated into CyberAtlas content and external destinations.

Suggested first hour

  1. 1 · Read what a port is and what an IP address is not.
  2. 2 · Open the Nmap entry and read the first three commands — do not run anything yet.
  3. 3 · Pick the Absolute Beginner path and set up its stage-one lab.

Concepts

One question per page, written to be finished in a few minutes and re-read later with more context.

10 entries

Practice labs

Isolated targets you own or are given access to. · 6 external destinations

Isolated environments only
  • Practice labBeginnerOWASP

    OWASP Juice Shop

    Deliberately vulnerable single-page web app with an integrated scoring server. Runs in Docker or Node on your own machine.

    Open external resource
  • Practice labBeginnerCommunity

    DVWA — Damn Vulnerable Web Application

    Small PHP/MySQL app with selectable difficulty, useful for watching how a fix changes behaviour.

    Open external resource
  • Practice labIntermediateRapid7

    Metasploitable 3

    Deliberately vulnerable VM image for network and host assessments in an isolated range.

    Open external resource
  • Practice labBeginnerOverTheWire

    OverTheWire: Bandit

    Wargame levels that teach SSH, permissions, pipes and grep by requiring them. The most common first stop before anything graphical.

    Open external resource
  • Practice labIntermediateCyberDefenders

    CyberDefenders

    Blue-team labs built on real memory, packet and disk images with question-driven analysis.

    Open external resource
  • Practice labIntermediateCyberDefenders

    Blue Team Labs Online

    Investigation challenges with evidence downloads; a natural companion to the forensics category.

    Open external resource

CTF resources

Competitions and archives, ranked by beginner-friendliness. · 4 external destinations

  • CTFBeginnerTryHackMe

    TryHackMe guided rooms

    Hand-held paths with in-browser VMs; useful when you want structure rather than a blank target.

    Open external resource
  • CTFIntermediateHack The Box

    Hack The Box

    Labs and competitive machines with write-ups gated behind the same access model as the ranges.

    Open external resource
  • CTFBeginnerCarnegie Mellon University

    picoCTF

    Long-running high-school CTF with a persistent practice archive — good for reverse engineering and forensics firsts.

    Open external resource
  • CTFIntermediateCommunity

    CTFtime

    Calendar and results index for CTFs. Use it to find an upcoming event rather than an archive.

    Open external resource

Certifications

What each exam actually measures, without the marketing. · 4 external destinations

  • CertificationBeginnerCompTIA

    CompTIA Security+

    Vendor-neutral baseline across vocabulary, controls and domains. Widely used as an HR keyword rather than a competence proof.

    Open external resource

    Issued by CompTIA

  • CertificationBeginnerINE

    eJPT

    Practical junior pentest exam in an assigned lab range; a common first hands-on certification.

    Open external resource

    Issued by INE

  • CertificationAdvancedOffSec

    OSCP

    24-hour practical exam against multiple lab machines with a report. Read the current exam description before preparing — it changes.

    Open external resource

    Issued by OffSec

  • CertificationAdvancedSANS/GIAC

    GIAC incident-handling certifications

    Defensive, incident-oriented credentials with substantial training cost attached; typically employer-funded.

    Open external resource

    Issued by GIAC

Books

Reference material that outlives tool versions. · 2 external destinations

  • BookIntermediateWiley

    The Web Application Hacker's Handbook (2e)

    Older than current framework defaults but still the clearest taxonomy of testing techniques and reasoning.

    Open external resource
  • BookIntermediateNo Starch Press

    Practical Malware Analysis

    Structured lab discipline for static and dynamic analysis; the exercises assume an isolated VM.

    Open external resource

Frameworks & references

Authoritative documents worth reading directly. · 4 external destinations

  • Framework / referenceMITRE

    MITRE ATT&CK

    Knowledge base of adversary tactics and techniques, used for detection mapping and coverage discussion.

    Open external resource
  • Framework / referenceOWASP

    OWASP Top 10

    A awareness document of recurring web risk categories — useful vocabulary, not a testing methodology or a standard.

    Open external resource
  • Framework / referenceNIST

    NIST Cybersecurity Framework 2.0

    Organisational functions (Govern, Identify, Protect, Detect, Respond, Recover) for structuring a programme.

    Open external resource
  • Framework / referenceRFC Editor

    RFC Editor index

    When a tutorial contradicts the protocol, read the protocol. HTTP, TCP, DNS and IP are all short reads at this point.

    Open external resource

Courses

Structured study with public materials. · 1 external destinations

  • CourseAdvancedUMD

    University of Maryland — CMSC 656 (open notes)

    Publicly posted course notes on network and systems security fundamentals; a rigorous free alternative to paid intros.

    Open external resource

Reading is not the whole path

Concepts and labs are inputs. A roadmap sequences them, and the tool pages carry the commands you will actually need.

27 tools and their commands sit behind every stage listed above.